Microsoft Defender for Cloud Apps
Cloud and workloads

Control cloud apps with policies

In brief

Updated metadata, link labels, wording, screenshot descriptions, and the Policies overview report heading and anchor.

What Defender admins need to know

No administrator action is required; the supplied changes only update the documentation presentation and navigation.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Control cloud apps with policies

Policy type icon Policy type Category Use
Icon for the activity policy type in Defender for Cloud Apps. Activity policy Threat detection Activity policies allow you to enforce a wide range of automated processes using the app provider's APIs. These policies enable you to monitor specific activities carried out by various users, or follow unexpectedly high rates of a certain type of activity. Learn about user activity policies
Icon for the anomaly detection policy type in Defender for Cloud Apps. Anomaly detection policy Threat detection Anomaly detection policies enable you to look for unusual activities on your cloud. Detection is based on the risk factors you set to alert you when something happens that is different from the baseline of your organization or from the user's regular activity. Learn about anomaly detection policies
Icon for the OAuth app policy type in Defender for Cloud Apps. OAuth app policy Threat detection OAuth app policies enable you to investigate which permissions each OAuth app requested and automatically approve or revoke it. OAuth app policies are built-in policies that come with Defender for Cloud Apps and can't be created. Learn about app permission policies
Icon for the malware detection policy type in Defender for Cloud Apps. Malware detection policy Threat detection Malware detection policies enable you to identify malicious files in your cloud storage and automatically approve or revoke it. Malware detection policy is a built-in policy that comes with Defender for Cloud Apps and can't be created. Learn about malware detection policies
Icon for the file policy type in Defender for Cloud Apps. File policy Information protection File policies enable you to scan your cloud apps for specified files or file types (shared, shared with external domains), data (proprietary information, personal data, credit card information, and other types of data) and apply governance actions to the files (governance actions are cloud-app specific). Learn about data protection policies

File policies retire on January 6, 2027. Migrate to Microsoft Purview DLP or auto-labeling policies.
Icon for the access policy type in Defender for Cloud Apps. Access policy Conditional Access Access policies provide you with real-time monitoring and control over user logins to your cloud apps. Learn about access policies
Icon for the session policy type in Defender for Cloud Apps. Session policy Conditional Access Session policies provide you with real-time monitoring and control over user activity in your cloud apps. Learn about session policies
Icon for the cloud discovery policy type in Defender for Cloud Apps. App discovery policy Shadow IT App discovery policies enable you to set alerts that notify you when new apps are detected within your organization. Learn about cloud discovery policies

Identifying risk

Alternatively, you can create a policy during investigation. If you're investigating the Activity log, Files, or Identities, and you drill down to search for something specific, at any time you can create a new policy based on the results of your investigation.

For example, you might want to create onea policy if you're looking at the Activity log, and see an admin activity from outside your office's IP addresses.

To create a policy based on investigation results, do the following steps:

  1. Use the filters at the top of the page to limit the search results to the suspicious area. For example, in the Activity log page, select Administrative activity and select True. Then, under IP address, select Category and set the value to not include IP address categories you've created for your recognized domains, such as your admin, corporate, and VPN IP addresses.

    Screenshot of Activity log filtered to administrative activity and untrusted IP categories for investigation.

  2. Below the query, select New policy from search.

    When using the policy filters, Contains searches only for full words – separated by comas, dots, spaces, or underscores. For example if you search for malware or virus, it finds virus_malware_file.exe but it does not find malwarevirusfile.exe.

Equals searches only for the complete string, for example if you search for malware.exe it finds malware.exe but not malware.exe.txt.

![Screenshot of creating anthe create activity policy page with pre-populated filters from an investigation result.query.](media/create-activity-policy-from-investigation.png)
  • To enable a policy, in the Policy page, select the three dots at the end of the row of the policy you want to enable. Select Enable.

    Screenshot of the policy context menu with the Enable command.

  • To disable a policy, in the Policy page, select the three dots at the end of the row of the policy you want to disable. Select Disable.

    Screenshot of the policy context menu with the Disable command.

By default, after you create a new policy, it's enabled.

View the Policies overview report

Defender for Cloud Apps lets you export a policies overview report showing aggregated alert metrics per policy to help you monitor, understand, and customize your policies to better protect your organization.

  1. In the table, select the relevant report, and then select download.

    Screenshot of the Exported reports page with the control to download a report.

Next steps